# Russian Threat Clusters Abuse OAuth and WhatsApp for Espionage

> Google Threat Intelligence reports three suspected Russian groups using OAuth phishing, Google app passwords, and WhatsApp device linking to hijack accounts.

- Published: 2026-08-23T16:14:39.000Z
- Severity: medium
- Category: Threat Intel
- Tags: APT29, Phishing, OAuth, Credential Theft, Malware
- Author: Runtime Rebel Intel
- Primary source: https://thehackernews.com/2026/08/suspected-russian-hackers-abuse-google.html
- Canonical: https://runtimerebel.com/blog/russian-threat-clusters-abuse-oauth-and-whatsapp-for-espionage

## Key points

- State-sponsored espionage campaigns are targeting defense, academic, and government personnel across Europe and the U.S. with targeted account takeovers.
- Attackers are abusing legitimate authentication flows including Google OAuth, application-specific passwords, Microsoft device codes, and WhatsApp device linking.
- Organizations must enforce phishing-resistant multi-factor authentication such as FIDO2 hardware keys and monitor for unauthorised OAuth app grants.

## Overview of Russian Espionage Clusters

Recent intelligence published by the Google [Threat Intelligence](/glossary#threat-intelligence) Group (GTIG) highlights three distinct suspected Russian threat clusters—**UNC6293**, **UNC5976**, and **UNC7005**—engaging in persistent and adaptive [phishing](/glossary#phishing) campaigns. According to [The Hacker News](https://thehackernews.com/2026/08/suspected-russian-hackers-abuse-google.html), these campaigns primarily target individuals working in academia, aerospace, defense, government sectors, and think tanks across Europe, Ukraine, Armenia, and the United States.

The activity underscores a broader shift among state-sponsored actors toward abusing legitimate cloud authentication mechanisms and platform features rather than relying solely on traditional [malware](/glossary#malware) payloads. By weaponizing trusted service flows, these adversaries bypass conventional security perimeters and trick users into willingly handing over access.

## Technical Analysis of Attack Vectors

The identified threat clusters employ sophisticated [social engineering](/glossary#social-engineering) themes, often impersonating diplomatic officials or using bespoke conference and event lures.

### OAuth and Application Password Abuse

UNC6293, assessed as a sub-cluster of [APT29](https://en.wikipedia.org/wiki/APT29) (also tracked as Cozy Bear or Midnight Blizzard), maintains a focus on low-volume, highly selective phishing. The group has historically utilized Google account application-specific passwords under diplomatic pretexts. More recently, the cluster has pivoted to OAuth token theft by tricking victims into sharing verification codes or full URLs after completing legitimate authentication steps.

Meanwhile, UNC5976 has automated token collection by deploying malicious cloud infrastructure behind file-sharing themed domains. Victims visiting these domains are presented with a fake login dialog featuring a legitimate "Continue with Google" prompt. Successful authentication redirects the user to a Google Cloud project hosting scripts that harvest the resulting authentication tokens. UNC5976 has also distributed a rogue Excel plugin codenamed HEADRUSH to deliver HTML Application loaders.

### WhatsApp Device Linking and Device Code Phishing

UNC7005 (also known as Storm-2945) has introduced novel social engineering tactics, including [spoofing](/glossary#spoofing) WhatsApp to hijack messaging accounts. Attackers lure targets into linking their WhatsApp accounts with an attacker-controlled device under the guise of joining a secure voice call, encrypted chat, or document share. Once the user scans the legitimate QR linking code, the adversary gains full access to the messaging account and executes malicious JavaScript to capture audio and video feeds.

Additionally, UNC7005 employs device code phishing against Microsoft accounts. These campaigns utilize sophisticated lures involving diplomatic event invitations, including customized dining and wine preferences that mirror historical Ice Relic tactics tracked elsewhere as SPIKEDWINE.

## Mitigations and Defense Guidance

Defending against authentication-abuse campaigns requires a multi-layered security posture that restricts reliance on easily phished credentials:

* **Deploy Phishing-Resistant [MFA](/glossary#mfa):** Transition away from SMS, push notifications, and basic app passwords toward FIDO2/WebAuthn-compliant hardware security keys which natively bind authentication to the legitimate origin.
* **Audit OAuth Grants:** Regularly review and restrict third-party application permissions across cloud tenant environments to detect unauthorized token generation and rogue cloud projects.
* **Monitor Device Linking:** Implement administrative alerts and visibility over corporate messaging and collaboration platforms for unexpected secondary device linking events.

**Related:** [Hotel Wi-Fi Campaigns Use CornFlake and ChocoShell Malware](/blog/hotel-wi-fi-campaigns-use-cornflake-and-chocoshell-malware), [Identity Abuse and Phishing via Enterprise Collaboration Platforms](/blog/identity-abuse-and-phishing-via-enterprise-collaboration-platforms)

---

AI-generated analysis from the primary source above; not human-reviewed before publication — verify anything operational against the original (https://runtimerebel.com/editorial). Quote with attribution and a link to the canonical URL: https://runtimerebel.com/blog/russian-threat-clusters-abuse-oauth-and-whatsapp-for-espionage
